Threats Tagged 'ghsa-x8gv-g2g3-65fj'
View all threats tagged with 'ghsa-x8gv-g2g3-65fj'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-x8gv-g2g3-65fj'
Click on any threat for detailed analysis and mitigation recommendations
SiYuan Agent Tools versions up to 3.8.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to a DNS rebinding time-of-check to time-of-use (TOCTOU) flaw. The vulnerability arises because the SSRF protection performs a single DNS resolution at guard time but does not verify the IP address at connection time, allowing an attacker-controlled domain to bypass the check by returning a public IP initially and a private or loopback IP on connection. This enables access to internal services such as cloud instance metadata. The issue affects the AI Agent tools' http_request and web_fetch components and was patched in version 3.8.1. Join the discussion | GCVE Database | 10/02/2026, 23:17:16 UTC Added: 10/03/2026, 17:21:44 UTC |
Showing 1 to 1 of 1 result